Solved

TLS 1.1  Should I use QWORD or DWORD and what ciphers should be added ?

Posted on 2014-11-10
5
320 Views
Last Modified: 2014-11-11
Windows 2008 R2 server, IIS 7.0.  I turned off the SSL 3.0 and turned on the TLS 1.1 in the registiry using the Microsoft instructions.  They scanned the server again and they are saying it's still  vunerable.

I used QWORD in the registry settings instead of DWORD since it's a 64 bit operating system.  Is QWORD Correct?

I was not sure if there were specific ciphers I needed to turn off also that may still be causing the problem?
0
Comment
Question by:kdschool
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 81

Assisted Solution

by:David Johnson, CD, MVP
David Johnson, CD, MVP earned 100 total points
ID: 40434259
they should be DWORD not QWORD
set-perfectFSecutity.ps1.txt
0
 
LVL 64

Accepted Solution

by:
btan earned 400 total points
ID: 40434303
indeed it is DWORD (32-bit) Value for client and server. And collectively do reference to Microsoft security advisory for the mitigation of the recent SSLv3 Poodle vulnerability. Note there are previous vulnerability such as BEAST which is along the line for disabling SSL v3 too. check out the browser setting and it will be good to push down as GPO to all managed machines and manually configure it for the standalone machine

https://technet.microsoft.com/en-us/library/security/3009008.aspx

You can also catch the screenshot steps below.

https://www.digicert.com/ssl-support/iis-disabling-ssl-v3.htm
0
 
LVL 63

Expert Comment

by:Simon Butler (Sembee)
ID: 40434472
I gave up using manual registry entries.
Try this free tool instead:

https://www.nartac.com/Products/IISCrypto/

Simon.
0
 
LVL 64

Expert Comment

by:btan
ID: 40434508
there is also some sharing of key note running reg, pls see in SAN posting (esp the feedbacks)
https://isc.sans.edu/forums/diary/POODLE+Turning+off+SSLv3+for+various+servers+and+client/18837
0
 

Author Closing Comment

by:kdschool
ID: 40435786
Can't use a tool through the firewall.  Thank you so much for the images.  That was spot on.
0

Featured Post

Free NetCrunch network monitor licenses!

Only on Experts-Exchange: Sign-up for a free-trial and we'll send you your permanent license!

Here is what you get: 30 Nodes | Unlimited Sensors | No Time Restrictions | Absolutely FREE!

Act now. This offer ends July 14, 2017.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Logparser is the smartest tool I have ever used in parsing IIS log files and there are many interesting things I wanted to share with everyone one of the  real-world  scenario from my current project. Let's get started with  scenario - How do w…
#SSL #TLS #Citrix #HTTPS #PKI #Compliance #Certificate #Encryption #StoreFront #Web Interface #Citrix XenApp
Come and listen to Percona CEO Peter Zaitsev discuss what’s new in Percona open source software, including Percona Server for MySQL (https://www.percona.com/software/mysql-database/percona-server) and MongoDB (https://www.percona.com/software/mongo-…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

688 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question